theHarvester discovery and evidence architecture An authorized finite run selects passive, DNS, or direct activity, then saves normalized findings with their provenance and producer outcomes for review and export. THEHARVESTER RUN From an authorized target to saved evidence Run selected sources and actions; keep each outcome with the findings. 01 · SCOPE Define the run One authorized target Selected sources Explicit actions FINITE · BOUNDED 02 · ACTIVITY Choose the boundary P0 Passive collection public providers / datasets P1 DNS interaction authorized names / addresses P2 Direct interaction selected target endpoints 03 · EXECUTE Run and record outcomes Collect observations Keep results so far Record producer outcomes COMPLETED · PARTIAL · FAILED RATE-LIMITED · SKIPPED 04 · EVIDENCE Normalize once Canonical kind + value Provenance survives deduplication Producer outcomes stay attached COMPLETE · PARTIAL · FAILED PARTIAL RESULTS theHarvester keeps results when one producer stops early. USE THE SAME EVIDENCE Review TERMINAL HARVESTVIEW Automate REST · JSONL Retain SQLITE Integrate JSON · XML